S

Data Security Engineer - Infosec

Sun Life · Thāne, Maharashtra, India

3–10 yrs experiencefull_timePosted 1w ago

Job description

Roles: The Data Security Engineer will be responsible for implementing and operating technical controls to protect sensitive, confidential and personal data across Aditya Birla Capitals technology environment. The role will focus on strengthening enterprise data security capabilities across DLP, data discovery, data classification, encryption, masking, tokenization, access monitoring and secure data handling. The jobholder will support the security control requirements emerging from regulatory, privacy and business expectations, including the DPDP Act, while ensuring that execution remains within the Information Security domain. The role will work closely with Information Technology, Cloud, Application, Infrastructure, SOC, Business and Privacy teams to identify where sensitive data resides, how it moves, who accesses it, and whether appropriate security controls are in place. The role will also drive user awareness and operational improvements to reduce accidental or intentional data leakage across users, applications, endpoints, cloud and third-party channels. Responsibility: **Key Result Areas** Supporting Actions Data Loss Prevention Implementation & Operations: Ensure effective implementation, monitoring and continuous improvement of DLP controls across enterprise channels. - Implement and maintain DLP policies across email, endpoint, web, removable media, cloud storage, SaaS and collaboration platforms. - Configure DLP rules for customer data, personal data, financial information, credentials, business confidential data and regulatory-sensitive information. - Monitor DLP alerts and support investigation, triage, escalation and closure of data leakage incidents. - Fine-tune DLP policies to reduce false positives and improve detection accuracy. - Identify repeat offenders, risky departments, high-risk channels and recurring leakage patterns. - Support integration of DLP alerts with SOC/SIEM workflows. - Maintain dashboards on DLP incidents, trends, open actions and control effectiveness. Data Discovery & Sensitive Data Visibility: Improve enterprise visibility into sensitive and confidential data across structured and unstructured environments. Shared KRA with privacy team: - Supporting implementation of data discovery tools across databases, file shares, endpoints, cloud workloads, SaaS platforms and collaboration tools. - Identify locations where personal data, customer data, financial data, authentication data and confidential business data are stored. - Support creation of sensitive data inventories from a security controls perspective. - Identify overexposed, stale, duplicate, unmanaged or high-risk sensitive data repositories. - Work with application, infrastructure, cloud and business teams to validate discovery results. - Track remediation of high-risk data stores, including excessive access, open shares and unmanaged exports. - Provide inputs to data owners and privacy teams on discovered sensitive data locations, without owning privacy compliance decisions. Data Classification & Labelling Controls: Enable classification-led security controls across ABCs data landscape. - Support implementation of data classification and labelling tools across documents, emails, files and repositories. - Configure classification labels for internal, confidential, restricted, customer-sensitive and regulatory-sensitive data categories. - Enable security controls based on classification, including DLP enforcement, encryption, access restriction and external sharing control. - Work with business and data owners to drive classification adoption. - Monitor classification coverage across critical repositories and user groups. - Identify unclassified or misclassified sensitive information and drive corrective actions. - Support automation of classification wherever feasible. Privacy Enhancing Technologies & Data Protection Engineering: Implement technical data protection mechanisms to reduce exposure of sensitive and personal data. Shared KRA with privacy team: - Support implementation of masking, tokenization, anonymization, pseudonymization and encryption controls. - Identify technology use cases where sensitive data exposure can be reduced through PETs. - Work with application, database, analytics and cloud teams to implement data protection controls. - Support controls for production data usage in non-production environments. - Validate whether sensitive data is appropriately protected at rest, in transit and during processing. - Support secure data usage in analytics, reporting, testing, AI/GenAI and third-party integrations. - Coordinate with platform and application teams to improve adoption of encryption, key management and secrets protection. Data Access Monitoring & Risk Reduction: Reduce risk from excessive, inappropriate or unmanaged access to sensitive data. - Support monitoring of access to sensitive data repositories, databases, file shares, reports and applications. - Identify excessive privileges, dormant accounts, orphaned access and risky access patterns. - Work with IAM, application and business teams to enforce least privilege and need-to-know access. - Support periodic access review exercises for high-risk data repositories. - Monitor bulk downloads, unusual access activity, large data exports and suspicious data movement. - Support database activity monitoring and privileged access monitoring for critical data platforms. - Track remediation of access-related findings and exceptions. Secure Data Handling Awareness: Improve user behaviour and reduce data leakage through focused awareness and adoption initiatives. - Develop awareness content on secure handling of customer data, confidential data and sensitive business information. - Conduct targeted awareness for users involved in repeated DLP violations or high-risk data handling. - Create short guides on secure email usage, external sharing, cloud storage, removable m